HSE Integrated Risk Management Policy. Part 3. Managing and Monitoring Risk Registers Guidance for Managers

Size: px
Start display at page:

Download "HSE Integrated Risk Management Policy. Part 3. Managing and Monitoring Risk Registers Guidance for Managers"

Transcription

1 HSE Integrated Management Policy Part 3 Managing and Monitoring Registers Guidance for Managers

2

3 HSE Integrated Management Policy Part 3 Managing and Monitoring Registers Guidance for Managers Identify Measure, Control and Monitor Management Analysis and Evaluation Implement Action Plan Action

4

5 TABLE OF CONTENTS 1. Introduction 4 2. Overview of the Management Process 4 3. Purpose 5 4. Scope 5 5. Definitions 5 6. Roles and Responsibilities 5 7. Maintaining the Register Updating existing risks on the register Inclusion of new risks on the register Reviewing the entirety of the register 7 8. Re-Rating 8 9. Changing the Status De-escalating Notification Related Policy and Guidance 9 Appendix 1: Definitions 10 3

6 1. Introduction management seeks to identify and manage those things that, should they occur, would prevent an organisation from achieving its objectives. It does this by estimating both the impact of the risk, i.e. how bad will the outcome of the risk be if it occurs and what is the likelihood that the event will happen. In a nutshell this means that rather than wait for things to go wrong (incidents) we should adopt an approach which anticipates what might go wrong and put in place any actions that may prevent an incident occurring. The upside of adopting a risk management approach is that we are more likely to achieve our objectives and less likely to have negative outcomes. It is however important to note that positive risk taking (as opposed to risk avoidance) within a framework of safety can and should be encouraged in order to support Service Users attain their potential. This is particularly relevant in social care settings where the ethos espoused is one of service user self-determination. The HSE s Integrated Management Policy recognises the importance of the HSE adopting a proactive approach to the management of risk to support both its achievement of objectives and compliance with governance requirements. The HSE is committed to developing a risk management culture, where a proactive approach to risk is integrated and embedded into management processes at all levels in the organisation and where all staff are alert to risks, capable of an appropriate level of risk assessment and confident to report risk or opportunities perceived to be important in relation to priorities. To support Managers in delivering on their commitments in relation to the HSE s Integrated Management Policy a number of pieces of guidance have been developed. A range of tools are also available, detail of which can be found on 2. Overview of the Management Process The HSE s approach to risk management is aligned to the ISO an overview of which is provided at Figure 1 below. Register Establishing the Context Identification Communicate and Consult Assessment Analysis Evaluation Monitor and Review Treatment Figure 1. Management Process 4

7 The process adopted requires Managers, within the context of their area of responsibility and in consultation with their staff, to identify analyse and evaluate risks and to put in place any treatment (actions) required to reduce those risks. Where a formal management plan is required the outcome of this process is documented in the relevant risk register and monitored and reviewed by the relevant Management Team. 3. Purpose The HSE has developed a number of pieces of guidance to support staff in complying with the HSE s Integrated Management Policy. These are Part 1 Managing in Everyday Practice Part 2 Assessment and Treatment Part 3 Managing and Monitoring Registers This is Part 3 of the guidance suite. The purpose of this guidance is to assist you and your Management Team with the process for managing and monitoring your risk register. 4. Scope This guidance is for use in the management of service and organisational related risk and applies to all staff that holds a management role at any level of the organisation. It applies to both HSE and HSE-funded services. 5. Definitions A full list of definitions relating to risk management terms used in this and supporting documents is contained in Appendix Roles and Responsibilities Whereas every staff member is responsible for identifying risk within the context of their work, risk management is a line management responsibility and is a core management process. The Line Manager is also responsible to check that the risk register in their area of responsibility is compliant with the HSE Integrated Management Policy and supporting Guidance. The role of the risk management professionals for example /QPS Advisors is to support, facilitate and advise Line Managers on the technical aspects of the risk management process i.e. they are not responsible for managing risk identified within a service area. 5

8 7. Maintaining the Register Updating the risk register is an ongoing process and updates can occur at any time however to ensure the register is actively reviewed and updated a scheduled process should be in place to ensure effective monitoring at Management Team. Whilst it is not the purpose of this guidance to dictate the frequency of review of the risk register there are three processes outlined which should attach to the maintenance of the register: 7.1 Updating existing risks on the register 7.2 Identifying and adding risks to the existing register 7.3 Reviewing the entirety of the register The following provides guidance in relation to each of these processes. 7.1 Updating existing risks on the register To enable this, the Lead should facilitate in association with Coordinators the following steps for existing risks on the register Action owners assigned must provide an update on progress to the Owner on any action assigned to them where the due date is due. Staff who identified the risk may also request an update on progress Where evidence is available that an action is implemented/complete and added control is evident this will be reflected in the risk register. In such an instance the additional control required should be closed and the new control should be reflected in the existing control section of the register Where the due date for an action has been reached and the action remains outstanding, the update should reflect the reason for this and a new due date should be proposed When the action updates have been reflected on the register, the revised register should, in advance of the Management Team meeting, be sent to Managers identified on the register as Coordinators. Coordinators in advance of the meeting must review each of the risks for which they are assigned a coordinating responsibility. This must include a review of the risk description to ensure it remains valid and a review of the existing controls. As the internal or external context may have changed since the risk was previously reviewed what were considered strong controls may no longer be applicable or some new ones may be now in place which are not related to the action plan and require inclusion in the register. Any areas requiring amendment should be notified immediately to the Lead so that these may be reflected in the register The Lead in consultation with Coordinators should also review the risk rating in context of the above and be in a position to recommend re-rating of the risk at the Management Team meeting if relevant. (Re-rating see Section 8 below). The Lead will provide a report to the Management Team which outlines actions due and complete, actions due and incomplete, actions due for the next period, existing controls whose status has changed, recommendations for re-rating (Re-rating see Section 8 below)/changing the risk status of existing risks (Changing the Status see Section 9 below)/de-escalation ( De-escalation see Section 10 below) The following will be agreed at Management Team in relation to the report Amended time frames for actions due and incomplete will be agreed Responsibility for identifying actions relating to any existing controls whose status has changed will be assigned to a member of the Management Team. Decide if any additional actions/controls above those already identified on the register are required. 6

9 Acceptance/rejection of recommendations for re-rating/de-escalation/changes to the risk status of existing risks. Consider whether any risks require notification to the Manager to which your service reports ( Notification see Section 11 below) It is recommended that the risk register should be reviewed on a monthly basis at the relevant Management Team meeting but at a minimum on a quarterly basis. Top Tip: To ensure effective use of time at the Management Team meeting updating of the register should be done in advance of the meeting. This will mean that the report brought can form the basis of any decision making required. To facilitate this, the Lead will require the timely cooperation of Coordinators and Management Team members. 7.2 Inclusion of new risks on the register The Management Team should agree the criteria for inclusion of new risks on the register. Such criteria may include risks that require a Management Team plan for example where actions may need to be allocated to a number of members of the Management Team, significant risks which require the direct oversight of the Management Team or risks notified from another level in the organisation Proposals for the addition of new risks onto the register can be made at any time but the decision to include these should be made at the Management Team. In such instances if it is decided that the risk should be included on the register, the Senior Manager will nominate a Coordinator to work with the Lead to conduct the analysis and evaluation of the risk and present this at the next meeting for sign off and inclusion on the register. Top Tip: Prior to commissioning the assessment of a new risk the Management Team should take time to clearly define the risk (see describing risk in Part 2 Assessment and Treatment Guidance for Managers). Time taken at this point will assist the Coordinator and Lead with the process for Analysis and Evaluation. 7.3 Reviewing the entirety of the register Though risk is monitored (on an ongoing basis as outlined above at relevant Management Team meetings), the Management Team should consider the entirety of the register periodically, ideally at a dedicated risk management meeting. Such a review process can assist in keeping the register relevant and allow for the identification of new risks and the archiving of risks that have been managed. It is recommended that the risk register should be reviewed in its entirety on a minimum of a bi-annual basis. Top Tip: As the definition of risk is the effect of uncertainty on objectives, one of these sessions should be linked to the business/service planning cycle i.e. what are your objectives for the coming year and what are the risks attaching to their achievement? 7

10 8. Re-Rating With the completion of some or all of the actions the level of risk (the rating) may be reassessed in order to consider whether its likelihood or impact score has reduced. For example, if a risk originally rated as having an 4 impact (major) x 5 likelihood (almost certain) before any additional controls were implemented it would have a risk score of 20 Red. 3. RISK MATRIX Negligible (1) Minor (2) Moderate (3) Major (4) Extreme (5) Almost Certain (5) Likely (4) Possible (3) Unlikely (2) Rare/Remote (1) Where following the implementation of additional controls the likelihood of the risk occurring was reassessed as having reduced from 5 (almost certain) to 4 (likely) but the impact stayed at 4, the overall risk rating will still be red but the numeric rating will have reduced from 20 to RISK MATRIX Negligible (1) Minor (2) Moderate (3) Major (4) Extreme (5) Almost Certain (5) Likely (4) Possible (3) Unlikely (2) Rare/Remote (1) Top Tip: In general, on re-rating it is the likelihood score that will reduce with the implementation of additional controls for example the better controlled a risk is the less likely it is to happen. Conversely, the impact score often stays the same as on the original assessment as if it does happen the impact remains the impact. Re-rating the risk should be done by the Lead in consultation with the person who acted as the Coordinator at the time the risk was initially assessed. This is because it is the Coordinator that has the expertise in relation to the subject matter of the risk and will be able to evaluate the extent to which the completion of additional controls serves to reduce or control the risk. Where implementation of actions does not appear to be serving to reduce the risk, consideration should be given to reviewing the appropriateness of the actions identified and revising the actions planned. Re-rating the risk assists in evidencing that the risk is being actively managed. 9. Changing the Status Whilst under active management, a risk has a status of being open. With the completion of actions and the mitigation of the risk, consideration can be given to changing its status to either monitor or closed. s with a status of monitor undergo periodic review for example quarterly or six monthly depending on the nature of the risk, to ensure that they remain mitigated as far as is reasonably practicable. s that have all required actions completed and require no further action are assigned a closed status are archived onto a closed register for audit purposes. 8

11 10. De-escalating In instances where a risk was notified to and accepted onto the register of a more Senior Manager for oversight it may be that following the implementation of actions the rating of the risk may have reduced to an acceptable or tolerable level or where remaining actions lie within the control of the Manager at the level below. In such circumstances a decision may be taken to close the risk on the register and to de-escalate it onto the register of the Manager on the level below. Such risks when added to the register below are given a risk status of open on that register and are reviewed at the next Management Team meeting of that Manager. 11. Notification It is essential that there are clear routes and processes for the communication and notification of risk from one level of the organisation to another. However it is also important to realise that such communication and notification does not absolve the responsibility of the Service Manager to which the risk relates of taking any actions required to mitigate it that are within their span of control. The risk therefore remains on their register. When a risk is notified to a more Senior Manager, that Manager can: Review the risk and decide not to accept it but seeks assurances in relation to the adequacy of its management within the referring service area. This can include the provision of resources/authorities to assist in its mitigation. Decide that the risk should be included on their risks register. Reasons for inclusion are generally due to one of two reasons: 1 That the significance of the risk is such that it requires oversight on their register, or 2 Thought the risk was identified by the area of the service that notified it, that it has resonance across the service as a whole and rather than just manage it on each individual register that many of the actions identified as required are better managed collectively. For example, if an overarching policy or process is required. On accepting the notified risk, the Manager arranges for it to be assessed in the context of their area of responsibility and includes it on their risk register. Any additional actions that are identified as being required are assigned according to the business rules, that is: to themselves, to members of their Management Team or to their Line Manager. The outcome of such considerations must be communicated back to the service that notified the risk. 12. Related Policy and Guidance HSE Integrated Management Policy, 2017 Managing in Everyday Practice Guidance for Managers ( Management Guidance Part 1, 2017) Assessment and Treatment Guidance for Managers ( Management Guidance Part 2, 2017) Policy and guidance are available at 9

12 Appendix 1: Definitions These definitions are predominantly based on the terms and definitions from the International Management Standard ISO 31000:2009. Controls A mechanism, process, procedure or action which can be verified, which seeks to reduce the likelihood and/or consequence of a risk. Controls include any process, policy, device, practice, or other actions which modify risk. They can exist or be required as additional in order to further mitigate the risk. Establishing the Context Defining the external and internal parameters to be taken into account when managing risk, and setting the scope and risk criteria for the risk management policy. Hazard A potential source of harm or adverse health effect on a person or persons. Impact The outcome or consequence of an event affecting objectives. It can be expressed either qualitatively or quantitatively, being a loss, disadvantage or gain. There may be a range of possible outcomes associated with an event. Likelihood The chance of something happening (also described as the probability or frequency of an event occurring). Line Manager A person with responsibility for directly managing individual employees or teams. In turn, they report to a higher level of management on the performance and well-being of the employees or teams they manage. Monitor To check, supervise, observe critically or record the progress of an activity, action or system on a regular basis in order to identify change. Operational Operational risks relate to the day-to-day delivery of activities, operational business plans and objectives. Operational risks typically have a short-term focus. Whilst they may impact a number of areas of the service, this does not necessarily make them a strategic risk. Operational risks may have the ability to impact strategic and other operational risks. Project Project risks relate to the achievement and delivery of the project objectives and outcomes. The majority of project risks are short term in nature and exist for the term of the project, whilst some will be on-going and re-classified at the end of the project. Projects can be defined as temporary, with the aim of delivering outcomes within a specified timeframe. Residual Rating The remaining level of risk after all treatment plans have been implemented. 10

13 is the effect of uncertainty on objectives. It is measured in terms of consequences and likelihood. In the context of the HSE and its services, it is any condition or circumstance which may impact on the achievement of objectives and/or have a significant impact on the day-to-day operations. This includes failing to maximise any opportunity that would help the HSE or service meet its objectives. Acceptance Informed decision to take a particular risk. Appetite Amount and type of risk that an organisation is willing to pursue or retain. Assessment Overall process of risk identification, risk analysis and risk evaluation. Avoidance Informed decision not to be involved in, or to withdraw from, an activity in order not to be exposed to a particular risk. avoidance may increase the significance of other risks or may lead to the loss of opportunities for gain. Categories The categories used by the organisation to group similar opportunities or risks for the purposes of reporting and assigning responsibility. Criteria Terms of reference against which the significance of a risk is evaluated. Description Structured statement of risk usually containing three elements: impact, cause and context. Evaluation Process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable. Identification A systematic process applied to the organisation s objectives and activities to identify possible risk sources and causes and potential consequences or impacts should a risk occur. Management Coordinated activities to direct and control an organisation with regard to risk. Management Process The systematic application of management policies, procedures and practices to the activities of communicating, consulting, establishing the context, and identifying, analysing, evaluating, treating, monitoring and reviewing risk. Matrix Tool for ranking and displaying risks by defining ranges for consequence and likelihood. Owner Person with the accountability and authority to manage a risk. Profile A risk profile is a written description of a set of risks. A risk profile can include the risks that the entire organsation must manage or only those that a particular function or part of the organisation must address. (In the HSE, a services risk profile is set out in their risk register). Rating The estimated level of risk taking into consideration the existing controls in place. 11

14 Source The source from which the risk was identified for example Incident Management, Audit, Health and Safety Assessment, Inspection Report, Complaint Register A risk register is a database of assessed risks that face any organisation at any one time. Always changing to reflect the dynamic nature of risks and the organisation s management of them, its purpose is to help Managers prioritise available resources to minimise risk and target improvements to best effect. Tolerance An organisation s or stakeholder s readiness to bear the risk after risk treatment in order to achieve its objectives. Strategic A strategic risk has the ability to impact on the achievement/delivery of the HSE s strategic objectives/directions. Strategic risks relate to the highest level of objective for the HSE, which typically have a long-term focus and are linked to the HSE s Strategic Plan. Treatment Additional mechanisms, processes, procedures or actions to be implemented, which seek to reduce the current likelihood and/or consequence and reach the Residual Rating. Directorate The Directorate is the governing authority of the HSE established following the enactment of the Health Service Executive (Governance) Act

15

16 Identify Contact details: Quality Assurance and Verification Division, Dr. Steevens Hospital, Dublin 8. Phone: Measure, Control and Monitor Management Analysis and Evaluation Publication Date: March 2017 Implement Action Plan Action

HSE Integrated Risk Management Policy. Part 1. Managing Risk in Everyday Practice Guidance for Managers

HSE Integrated Risk Management Policy. Part 1. Managing Risk in Everyday Practice Guidance for Managers HSE Integrated Risk Management Policy Part 1 Managing Risk in Everyday Practice Guidance for Managers HSE Integrated Risk Management Policy Part 1 Managing Risk in Everyday Practice Guidance for Managers

More information

RISK MANAGEMENT STRATEGY

RISK MANAGEMENT STRATEGY RISK MANAGEMENT STRATEGY 2015-2020 2016 Amendments This is a five-year strategy that is subject to annual review by the Board of Directors. The first review took place on 29 November 2016. At this time

More information

Risk Management Policy

Risk Management Policy Risk Management Policy 2015 Steadfast Group Limited ABN: 98 073 659 677 Risk Management Policy 1 ABN: 98 073 659 677 2013 Steadfast Group Limited Contents 1. INTRODUCTION 2 2. POLICY INTENT 2 3. POLICY

More information

Board Corporate Governance and Risk Committee

Board Corporate Governance and Risk Committee Policy Risk management Authorising Committee / Department: Responsible Committee / Department: Document Code: Board Corporate Governance and Risk Committee POL OPCEO Risk management Introduction The purpose

More information

RISK MANAGEMENT FRAMEWORK

RISK MANAGEMENT FRAMEWORK RISK MANAGEMENT FRAMEWORK Document Type Policy Document owner Lucinda Parr (Secretary and Registrar) Approved by Council Approval date 05 July 2017 Review date Version 1.0 Amendments Related Policies &

More information

Risk Management Strategy

Risk Management Strategy Risk Management Strategy 2017-2019 Created by: Role Name Title Author / Editor Kevin McMahon Head of Risk Management & Resilience Lead Executive Margo McGurk Director of Finance & Performance Approved

More information

Active Essex Risk Management Strategy

Active Essex Risk Management Strategy Active Essex Risk Management Strategy 2017-2021 November 2017 Contents 1. Policy Statement 2. Statement of Commitment 3. Risk Management Framework 4. Risk Appetite 5. Risk Maturity 6. Risk Management Levels

More information

Risk Management and Assurance Strategy

Risk Management and Assurance Strategy Risk Management and Assurance Strategy Version 5.0 Policy number ULHT-MD-GOV-RM-STRAT Document author(s) Head of 2021 Programme Contributor(s) Approved by Policy Approval Group Date approved Date Published

More information

RISK MANAGEMENT STRATEGY AND POLICY

RISK MANAGEMENT STRATEGY AND POLICY NEWPORT COMMUNITY SCHOOL PRIMARY ACADEMY Date Adopted: 12 th July 2012 Author/owner: Resources Committee Anticipated Review: Ongoing RISK MANAGEMENT STRATEGY AND POLICY Risk Management Strategy The Governing

More information

This policy establishes the approach to risk management at Sunshine Coast Council (Council) and outlines the guiding principles and framework.

This policy establishes the approach to risk management at Sunshine Coast Council (Council) and outlines the guiding principles and framework. Organisational policy Risk Management Policy Corporate Plan reference: Endorsed by Chief Executive Officer: Manager responsible for policy: A strong community In all our communitites, people are included,

More information

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk

Identifies the risk management structure, roles, responsibilities and authority of staff, committees and groups with responsibility for risk Title Description of document The sets out the process by which the Trust identifies, manages, reduces and mitigates risks to achieving the organisational objectives. It sets out the framework required

More information

Somalia. Risk Management For NGOs. Risk Management Unit United Nations Somalia

Somalia. Risk Management For NGOs. Risk Management Unit United Nations Somalia Somalia Risk Management For NGOs Risk Management Unit United Nations Somalia Table of Contents 1 GLOSSARY... 4 2 HOW TO USE THIS DOCUMENT... 6 3 OVERVIEW... 7 3.1 FRAGILE STATES, UNCERTAINTY AND RISK...

More information

Risk Management Strategy

Risk Management Strategy NHS Greater Glasgow & Clyde Strategy Strategy NHS GREATER GLASGOW & CLYDE Issue date: April 2007 Version: 1. Custodian: Head of Clinical Governance Status: Approved Review Interval: Two years 1 of 11 NHS

More information

Appendix 1 Detailed Internal Audit Strategic Planning Process

Appendix 1 Detailed Internal Audit Strategic Planning Process AUDIT RISK ASSESSMENT AND PLANNING Introduction The objective of this paper is to explain the assessment criteria and methodology employed in formulating an Audit Risk Assessment and how this is used to

More information

Northern Ireland Blood Transfusion Service

Northern Ireland Blood Transfusion Service Northern Ireland Blood Transfusion Service Risk Management Strategy 2018 Northern Ireland Blood Transfusion Service Lisburn Road Belfast BT9 7TS Telephone No. 028 9032 1414 www.nibts.org Page 1 of 13 CONTENTS

More information

RISK MANAGEMENT POLICY

RISK MANAGEMENT POLICY RISK MANAGEMENT POLICY Clinical Governance & Risk Management Department Warning Document uncontrolled when printed Policy Reference: RM 2.0 Date of Issue: TBC Prepared by: Risk Management Short Life Date

More information

Risk Management Policy

Risk Management Policy 9 Spokes International Limited Risk Management Policy Last Updated: May 2016 9 Spokes International Limited Risk Management Policy 1 Contents 1 Introduction... 3 2 Purpose... 3 3 Scope... 3 4 General roles

More information

RISK MANAGEMENT STRATEGY

RISK MANAGEMENT STRATEGY RISK MANAGEMENT STRATEGY Version 2.0 Page 1 of 9 OCTOBER 2013 POLICY DOCUMENT VERSION CONTROL CERTIFICATE TITLE Title: Risk Management Strategy Version: 2.0 SUPERSEDES Supersedes: Risk Management Strategy

More information

DIGGING DEEPER. CEO Guide to Risk. Take a closer look. Detailed questions to assess the effectiveness of your health and safety risk management

DIGGING DEEPER. CEO Guide to Risk. Take a closer look. Detailed questions to assess the effectiveness of your health and safety risk management CEO Guide to Risk DIGGING DEEPER Detailed questions to assess the effectiveness of your health and safety risk management Take a closer look This guide will help CEOs dig deeper into the effectiveness

More information

Risk Management Policy and Framework

Risk Management Policy and Framework Risk Management Policy and Framework Introductory Note to User: CompanyLongName There is no requirement in Australia for a non-publicly listed entity (other than a company regulated by APRA) to comply

More information

MAINTAINING THE HSE CORPORATE RISK REGISTER. Guidance Document

MAINTAINING THE HSE CORPORATE RISK REGISTER. Guidance Document MAINTAINING THE HSE CORPORATE RISK REGISTER Guidance Document Document reference number Document developed by Revision number 1.0 Document approved by Approval date February 2011 Responsibility for implementation

More information

The Urbis Academy Trust Risk Management Strategy

The Urbis Academy Trust Risk Management Strategy The Urbis Academy Trust Risk Management Strategy 1.0 Introduction 1.1 Risk management is the process whereby the School/Trust methodically addresses the risks attaching to its objectives and associated

More information

Risk Management Update ISO Overview and Implications for Managers

Risk Management Update ISO Overview and Implications for Managers Contents - ISO 31000 highlights 1 - Changes to key terms and definitions 2 - Aligning key components of the risk management framework 3 - The risk management process 4 - The principles of risk management

More information

Quality, Safety & Risk Management Framework Policy and Procedure Policy Number 023

Quality, Safety & Risk Management Framework Policy and Procedure Policy Number 023 Title: Quality Safety Management Document Control Policy Title Quality, Safety & Management Framework Policy Number 023 Owner Quality, Compliance & Training Manager Contributors Quality, Compliance & Training

More information

Statement on Risk Management and Internal Control

Statement on Risk Management and Internal Control INTRODUCTION The Board affirms its overall responsibility for the Group s system of internal control and risk management and for reviewing the adequacy and effectiveness of the system. The Board is pleased

More information

Governance Institute of Australia Ltd

Governance Institute of Australia Ltd Governance Institute of Australia Ltd Management Policy 1. Overview management is a key element of effective corporate governance. In view of this, Governance Institute of Australia Ltd (Governance Institute)

More information

CCG CO12 Policy and Framework for Partnership Governance

CCG CO12 Policy and Framework for Partnership Governance Corporate CCG CO12 Policy and Framework for Partnership Governance Version Number Date Issued Review Date V2: 21/02/2015 29/04/2015 21/02/2018 Prepared By: Consultation Process: Formally Approved: 25/02/2015

More information

COMPLIANCE MANAGEMENT FRAMEWORK FOR VICTORIA UNIVERSITY

COMPLIANCE MANAGEMENT FRAMEWORK FOR VICTORIA UNIVERSITY COMPLIANCE MANAGEMENT FRAMEWORK FOR VICTORIA UNIVERSITY July 2018 Prepared by: Policy Services (Compliance) Portfolio of the Vice-President (Planning) and Registrar Contents 1. BACKGROUND... 2 2. COMMITMENT

More information

COMPLIANCE MANAGEMENT FRAMEWORK. Conceptual Design Document

COMPLIANCE MANAGEMENT FRAMEWORK. Conceptual Design Document COMPLIANCE MANAGEMENT FRAMEWORK Conceptual Design Document 18 February 2013 1. INTRODUCTION & SUMMARY The purpose of the Compliance Management Framework is to ensure the University meets all of its external

More information

Enhanced Risk Management Policy

Enhanced Risk Management Policy Enhanced Risk Management Policy Approved By: City Council Category: General Administration Approval Date: September 12, 2001 Effective Date: September 12, 2001 Revision Approved By: Revision Date: August,

More information

RISK MANAGEMENT STRATEGY

RISK MANAGEMENT STRATEGY Agenda Item No: 15 RISK MANAGEMENT STRATEGY PURPOSE: The Risk Management Strategy has been updated to reflect the revised approach to the Corporate Risk Register and Board Assurance Framework and to reflect

More information

Health and Safety Policy Standard

Health and Safety Policy Standard Health and Safety Policy Standard Issue Date: 1 st July 2010 Authority: Directors, AES Group Applicability: AES Group covering all business divisions, operating companies and business units throughout

More information

Guidance Material. SMS Manual Format - Scalable. Notice to Users

Guidance Material. SMS Manual Format - Scalable. Notice to Users Guidance Material SMS Manual Format - Scalable Notice to Users This document is an advanced version of a draft CAA publication (proposed appendix to draft Advisory Circular AC137-1 Agricultural Aircraft

More information

Operational Risk Management Policy

Operational Risk Management Policy Contents Introduction & Scope... 2 Risk Management... 3 Risk Management Objectives... 3 Categorising Risk at an Organisational Level... 3 Risk Management Processes... 4 Risk Management Activities... 6

More information

Risk Management Policy

Risk Management Policy Risk Management Policy IPH Limited ACN 169 015 838 1. Introduction Organisations of all types and scale face internal and external factors and influences that make it uncertain whether and when they will

More information

ISO INTERNATIONAL STANDARD. Risk management Principles and guidelines. Management du risque Principes et lignes directrices

ISO INTERNATIONAL STANDARD. Risk management Principles and guidelines. Management du risque Principes et lignes directrices INTERNATIONAL STANDARD ISO 31000 First edition 2009-11-15 Risk management Principles and guidelines Management du risque Principes et lignes directrices http://mahdi.hashemitabar.com Reference number ISO

More information

Business Continuity Management Policy. Guidance

Business Continuity Management Policy. Guidance Management Guidance Document Type: Guidance Parent Policy: Management Policy Policy Owner: Chief Supt Department: Document Writer: Co-ordinator Effective Date: 12 th March 2015 Review Date: 12 th March

More information

Information Security Risk Management Programme and Strategy

Information Security Risk Management Programme and Strategy Information Security Risk Management Programme and Strategy Table of Contents 1. Introduction... 3 2. Purpose... 3 3. Definitions... 3 4. Roles and Responsibilities... 4 4.1. Accountable Officer... 4 4.2.

More information

CEO GUIDE TO RISK. Management and governance of health and safety risk

CEO GUIDE TO RISK. Management and governance of health and safety risk CEO GUIDE TO RISK Management and governance of health and safety risk Help to keep your people safe, meet your due diligence duties and build a more resilient business RISK RELATIONSHIPS RESOURCES www.zeroharm.org.nz

More information

Risk Management Guidelines of the CGIAR System

Risk Management Guidelines of the CGIAR System Agenda Item 11 For Decision Management Guidelines of the CGIAR System Purpose These guidelines are proposed as a companion document to the Management Framework of the CGIAR System to support the attainment

More information

Clause-byclause. Interpretation. Transitioning to ISO 9001:2015

Clause-byclause. Interpretation. Transitioning to ISO 9001:2015 We re committed to helping you and your organization understand the updated requirements. This guidance document identifies the steps you should take to achieve compliance to ISO 9001:2015, and more importantly;

More information

The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II

The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II The COSO Risk Framework: A reference for internal control? Transition from COSO I to COSO II S P E A K E R : D O T T. FA B I O A C C A R D I C O U R S E O F B U S I N E S S A U D I T I N G U N I V E R

More information

Asbestos Management. Final Internal Audit Report 2018/19. Powys Teaching Health Board. NHS Wales Shared Services Partnership

Asbestos Management. Final Internal Audit Report 2018/19. Powys Teaching Health Board. NHS Wales Shared Services Partnership Final Internal Audit Report 2018/19 NHS Wales Shared Services Partnership Audit and Assurance Services Reasonable Assurance - + Previous rating: 2012/13 Limited Assurance Report Contents CONTENTS Page

More information

Loch Lomond & The Trossachs National Park Authority. Annual internal audit report Year ended 31 March 2015

Loch Lomond & The Trossachs National Park Authority. Annual internal audit report Year ended 31 March 2015 Loch Lomond & The Trossachs National Park Authority Annual internal audit report Year ended 31 March 2015 Contents This report is for: Information Chief executive Audit committee Jaki Carnegie, director

More information

RISK MANAGEMENT - FRAMEWORK. OBJECTIVE To outline the Bay of Plenty District Health Board (BOPDHB) framework for risk management

RISK MANAGEMENT - FRAMEWORK. OBJECTIVE To outline the Bay of Plenty District Health Board (BOPDHB) framework for risk management OBJECTIVE To outline the Bay of Plenty District Health Board (BOPDHB) framework for risk management STANDARD All employees are responsible for ongoing identification of risk. Risk management at BOPDHB

More information

Recruitment Consultant Level 3 End Point Assessment

Recruitment Consultant Level 3 End Point Assessment Recruitment Consultant Level 3 End Point Assessment 1. Introduction This Assessment Plan for the Recruitment Consultant Apprenticeship has been designed and developed by employers with input from professional

More information

Why BSI? Our products and services. To find out more visit: bsigroup.com/en-au. Conclusion

Why BSI? Our products and services. To find out more visit: bsigroup.com/en-au. Conclusion Conclusion Risk-based thinking is not new Risk-based thinking is something you do already Risk-based thinking is continuous Risk-based thinking ensures greater knowledge and preparedness Risk-based thinking

More information

Alternative Resource Account Governance Process

Alternative Resource Account Governance Process Alternative Resource Account Governance Process Document Author: Alternative Resource Account Manager Date Approved: 26 th September 2018 Document Reference PO Alternative Resource Account Governance Process

More information

NIFRS Assurance Framework

NIFRS Assurance Framework NIFRS Assurance Framework March 2014 CONTENTS Page 1 Introduction 1 2 Planning & Risk Assessment 2 3 Building an Assurance Framework 2 4 Roles & Responsibilities 5 5 Assessing the Assurance Framework 7

More information

Risk Management Policy Arvind Infrastructure Limited

Risk Management Policy Arvind Infrastructure Limited Risk Management Policy Arvind Infrastructure Limited 0 Risk management 1.1 Purpose Arvind Infrastructure Limited is committed to high standards of business conduct and to good risk management to: 1. achieve

More information

Asset Risk Management Journey Plan

Asset Risk Management Journey Plan Asset Risk Management Journey Plan STRATEGIC PLAN 2010-2013 Transpower New Zealand Limited April 2011 TABLE OF CONTENTS EXECUTIVE SUMMARY... 3 1. PURPOSE... 4 2. OVERVIEW OF TRANSPOWER S RISK MANAGEMENT

More information

Risk Management Strategy Review. Deloitte recommendations and Implementation Plan

Risk Management Strategy Review. Deloitte recommendations and Implementation Plan Risk Management Strategy Review Deloitte recommendations and Implementation Plan 1. Purpose 1.1. This paper provides the results of the annual review of the current Risk Management Strategy. The results

More information

Business Continuity Policy

Business Continuity Policy Putting Barnsley People First Business Continuity Policy Version:.0 Approved By: Governing Body Date Approved: August 015 Reviewed October 016 Name of originator / author: Jamie Wike, Head of Planning,

More information

Risk Assessment Policy

Risk Assessment Policy Risk Assessment Policy Version: V2_0 September 2017 Owner: HR/Corporate Services Approved by: Executive Team 1 CONTENTS PAGE NUMBER 1. Purpose & Scope 3 2. Definitions 3-4 3. Roles & Responsibilities 4-5

More information

RISK MANAGEMENT STRATEGY

RISK MANAGEMENT STRATEGY INSTITUTE of GRUNDSANSIP (IG) RISK ANAGEENT STRATEGY INTRDUCTIN 1.In order for the IG to operate, deliver our services and achieve our objectives some amount of risk taking is necessary. The only way to

More information

HEALTH & SAFETY POLICY

HEALTH & SAFETY POLICY 1. Policy Statement CONTENTS 1. Policy Statement 2. Responsibilities 3. In Practice 3.1 Risk Assessments 3.2 COSHH 3.3 PPE 3.4 Safety Training 3.5 Accident Procedure 3.6 Emergency Procedure 3.7 Site Audits

More information

Risk Management Strategy

Risk Management Strategy Risk Management Strategy Risk Management Strategy 2016-2018 Janet Young Governance & Risk Manager June 2016 Executive Lead Jane Meggitt, Director of Communications & Corporate Affairs Index Foreword...............

More information

RISK MANAGEMENT REPORT

RISK MANAGEMENT REPORT RISK MANAGEMENT REPORT RISK POLICY STATEMENT Robust and effective management of risks is an essential and integral part of corporate governance. It helps to ensure that the risks encountered in the course

More information

Following up recommendations/management actions

Following up recommendations/management actions 22 March 2018 Following up recommendations/management actions Chartered Institute of Internal Auditors At the conclusion of an audit, findings and proposed recommendations are discussed with management

More information

United Lincolnshire Hospitals NHS Trust. Governance Statement 2015/16. Scope of responsibility. The governance framework of the organisation

United Lincolnshire Hospitals NHS Trust. Governance Statement 2015/16. Scope of responsibility. The governance framework of the organisation United Lincolnshire Hospitals NHS Trust Governance Statement 2015/16 Scope of responsibility As Accountable Officer, and Chief Executive of this Board, I have responsibility for maintaining a sound system

More information

SAFETY AND HEALTH AUDIT STRATEGY Safety & Health Services Safety and Health Audit Strategy Version 1.0

SAFETY AND HEALTH AUDIT STRATEGY Safety & Health Services Safety and Health Audit Strategy Version 1.0 SAFETY AND HEALTH AUDIT STRATEGY 2016-2019 Safety & Health Services Contents 1. INTRODUCTION... 1 2. AIMS AND OBJECTIVES... 1 3. DEFINITIONS... 1 AUDIT... 1 ASSURANCE... 1 AUDIT SPONSOR... 1 AUDIT OPINION...

More information

CONDUCTING 2X2 TASK RISK ANALYSIS CS-OHS-46

CONDUCTING 2X2 TASK RISK ANALYSIS CS-OHS-46 CS-OHS-46 (Amd 01/11) CS ENERGY PROCEDURE FOR A CONDUCTING 2X2 TASK RISK ANALYSIS CS-OHS-46 Responsible Officer: Group Manager Health and Safety Approved: GM Corporate CONTENTS 1 Purpose... 2 2 Context...

More information

Culture and behaviours Creating confidence in your biggest asset

Culture and behaviours Creating confidence in your biggest asset www.pwc.com/riskassurance Culture and behaviours Creating confidence in your biggest asset The executive summary series paper No.6 People are an organisation s greatest asset and also its greatest potential

More information

Risk Appetite Statement

Risk Appetite Statement Risk Appetite Statement May 2018 Risk Appetite Statement Contents 1. Mission, Vision, Values and Beliefs... 3 2. Introduction... 3 3. Overall Risk Appetite... 4 4. Risk Framework... 4 5. Key Risk Appetite

More information

2 ConocoPhillips Health, Safety and Environmental Management System

2 ConocoPhillips Health, Safety and Environmental Management System Section 2 summary 64 2.1 Overview 65 2.2 ConocoPhillips HSEMS Standard 65 2.2.1 Element 1: Policy and leadership 66 2.2.2 Element 2: Risk assessment 66 2.2.3 Element 3: Legal requirements and standards

More information

For: Information Assurance Discussion and input Decision/approval. Ellen Bull, Deputy Director of Quality Author Contact Details: 3531

For: Information Assurance Discussion and input Decision/approval. Ellen Bull, Deputy Director of Quality Author Contact Details: 3531 Trust Board Item: 15 Date: 07/02/2018 Purpose of the Report: Enclosure: K To request ratification from the Trust Board of Directors on the. which was discussed, refined and approved at the Risk Management

More information

Information and Guidance relating to the Review of Unit Standards Registered on the NQF of Namibia

Information and Guidance relating to the Review of Unit Standards Registered on the NQF of Namibia Information and Guidance relating to the Review of Unit Standards Registered on the NQF of Namibia NQA Council Resolution: 2010/03/25/7 Table of Contents Introduction... 3 Key terms... 4 Review of Unit

More information

RISK MANAGEMENT POLICY

RISK MANAGEMENT POLICY RISK MANAGEMENT POLICY Originated by Audit Committee: 17 September 2008 Approved by Council: 6 October 2008 Revised: July 2017 Revised approved by Council: 27 November 2017 Review Date: June 2019 Purpose

More information

Loch Lomond & The Trossachs National Park Authority and Cairngorms National Park Authority

Loch Lomond & The Trossachs National Park Authority and Cairngorms National Park Authority Loch Lomond & The Trossachs National Park Authority and Cairngorms National Park Authority Internal audit report 2014-15 Project Management 15 January 2015 Contents This report is for: Action David Cameron

More information

This Policy supersedes the following Policy, which must now be destroyed:

This Policy supersedes the following Policy, which must now be destroyed: Document Title Reference Number Lead Officer Author(s) (name and designation) Ratified by Forensic Readiness Policy NTW(O)56 Lisa Quinn Executive Director of Performance and Assurance Sue Proud Information

More information

Risk Management Strategy

Risk Management Strategy RM02 Lincolnshire Partnership NHS Foundation Trust (LPFT) Risk Management Strategy Document Type and Title: Authorised Document Folder: New or Replacing: Document Reference: DOCUMENT VERSION CONTROL Strategy

More information

HEALTH AND SAFETY STRATEGY

HEALTH AND SAFETY STRATEGY HEALTH AND SAFETY STRATEGY 2016-2019 Version: 1.0 Ratified by: Integrated Governance Committee Date ratified: 30 September 2015 Title of originator/author: Title of responsible committee/group: Head of

More information

Workplace HSE & Process Safety Consultancy

Workplace HSE & Process Safety Consultancy Company Profile Applied KPI Ltd provides consultancy in the following business critical disciplines: Process Safety; and Workplace HSE (Health, Safety and Environment). About Us Applied KPI was founded

More information

Guidance Note: Corporate Governance - Board of Directors. January Ce document est aussi disponible en français.

Guidance Note: Corporate Governance - Board of Directors. January Ce document est aussi disponible en français. Guidance Note: Corporate Governance - Board of Directors January 2018 Ce document est aussi disponible en français. Applicability The Guidance Note: Corporate Governance - Board of Directors (the Guidance

More information

Opportunities for Improvements in Safety and Health Management Systems for Coal Mines - An Auditor's Perspective

Opportunities for Improvements in Safety and Health Management Systems for Coal Mines - An Auditor's Perspective University of Wollongong Research Online Coal Operators' Conference Faculty of Engineering and Information Sciences 2009 Opportunities for Improvements in Safety and Health Management Systems for Coal

More information

SIZA Audit Frequency Matrix

SIZA Audit Frequency Matrix SIZA Audit Frequency Matrix May 2017 Overview The SIZA programme aims to build into the scheme robust assurances of the management of risk in respect of the supply base in the South African fruit industry.

More information

Chelsea & Westminster Hospital NHS Foundation Trust. Data protection audit report

Chelsea & Westminster Hospital NHS Foundation Trust. Data protection audit report Chelsea & Westminster Hospital NHS Foundation Trust Data protection audit report Executive summary October 2017 1. Background The Information Commissioner is responsible for enforcing and promoting compliance

More information

Title of Meeting: Governing Body Agenda Item: 7.4

Title of Meeting: Governing Body Agenda Item: 7.4 Title of Meeting: Governing Body Agenda Item: 7.4 Date of Meeting: 6 April 2017 Paper Title: HaRD CCG Draft Governing Body Assurance Framework Refresh Responsible Governing Body Member Lead Joanne Crewe,

More information

NOT PROTECTIVELY MARKED

NOT PROTECTIVELY MARKED NOT PROTECTIVELY MARKED Meeting Audit Committee Date 24 July 2018 Location Pacific Quay, Glasgow Title of Paper Internal Audit Organisational Change Report Item Number 5.5 Presented By Campbell McLundie,

More information

IRM s Professional Standards in Risk Management PART 1 Consultation: Functional Standards

IRM s Professional Standards in Risk Management PART 1 Consultation: Functional Standards IRM s Professional Standards in Risk PART 1 Consultation: Functional Standards Setting standards Building capability Championing learning and development Raising the risk profession s profile Supporting

More information

GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2))

GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2)) GUIDANCE NOTE FOR DEPOSIT TAKERS (Class 1(1) and Class 1(2)) Operational Risk Management MARCH 2017 STATUS OF GUIDANCE The Isle of Man Financial Services Authority ( the Authority ) issues guidance for

More information

Position Description. Position HSEQ Operations Manager Date July 2018

Position Description. Position HSEQ Operations Manager Date July 2018 Position HSEQ Operations Manager Date July 2018 Business Unit HSE and Quality Location New Plymouth Purpose This role exists by working as part of the HSEQ Leadership Team to: Lead a team of Advisors to

More information

RISK MANAGEMENT POLICY AND PROCEDURES AD-P009

RISK MANAGEMENT POLICY AND PROCEDURES AD-P009 1. OVERVIEW In managing risk, it is the Company's practice to take advantage of potential opportunities while managing potential adverse effects. Managing risk is the responsibility of everyone in the

More information

Head of HSE. Group Services, Risk

Head of HSE. Group Services, Risk Policy Title: Document Owner: Owning Department: Classification: Environmental Sustainability Policy Head of HSE Group Services, Risk KCOM Group Internal use only Business Units affected by this Policy:

More information

City of Melville Risk Management Toolkit

City of Melville Risk Management Toolkit City of Melville Risk Management Toolkit Last Review Date: 30/07/2012 Document Owner: Risk Management Coordinator Page 1 of 24 Table of Contents 1. Introduction... 3 2. Risk Management Methodology... 3

More information

Certification Candidates Examination Guide

Certification Candidates Examination Guide Certification Candidates Examination Guide Certification Candidates Examination Guide V2 5 Page 1 of 15 Contents Introduction... 3 Knowledge Based Examination... 3 Body of Knowledge... 3 1. Domains...

More information

British Gas Report to Ofgem in response to Ofgem s open letter on Supplier Complaints Handling dated 26th September 2014

British Gas Report to Ofgem in response to Ofgem s open letter on Supplier Complaints Handling dated 26th September 2014 British Gas Report to Ofgem in response to Ofgem s open letter on Supplier Complaints Handling dated 26th September 2014 britishgas.co.uk 1. Introduction from Ian Peters Managing Director British Gas One

More information

National Health and Safety Function, Workplace Health and Wellbeing Unit, National HR Division. Guideline Document

National Health and Safety Function, Workplace Health and Wellbeing Unit, National HR Division. Guideline Document National Health and Safety Function, Workplace Health and Wellbeing Unit, National HR Division Guideline Document Ref: GD:004:00 RE: Completion of Occupational Safety and Health Risk Assessments Issue

More information

Date: INFORMATION GOVERNANCE POLICY

Date: INFORMATION GOVERNANCE POLICY Date: INFORMATION GOVERNANCE POLICY Information Governance Policy IGPOL/01 Information Systems Corporate Services Division March 2017 1 Revision History Version Date Author(s) Comments 0.1 12/12/2012 Helen

More information

COCA-COLA HELLENIC BOTTLING COMPANY RISK MANAGEMENT POLICY

COCA-COLA HELLENIC BOTTLING COMPANY RISK MANAGEMENT POLICY COCA-COLA HELLENIC BOTTLING COMPANY RISK MANAGEMENT POLICY 1. INTRODUCTION The effective management of risk is central to the ongoing success and resilience of Coca-Cola Hellenic Bottling Company (CCHBC).

More information

ISO Revisions. ISO 9001 Whitepaper. The importance of risk in quality management. Approaching change

ISO Revisions. ISO 9001 Whitepaper. The importance of risk in quality management. Approaching change ISO Revisions ISO 9001 Whitepaper The importance of risk in quality management Approaching change Background and overview to the ISO 9001:2015 revision As an International Standard, ISO 9001 is subject

More information

West Kent Clinical Commissioning Group

West Kent Clinical Commissioning Group West Kent Clinical Commissioning Group Information Governance Strategy 2017-18 Release: Final Approved Date: 27/10/2016 Author: Jamie Sheldrake Senior Associate - Information Governance Owner: SOUTH EAST

More information

Risk Register - Education Department Risks and Mitigations

Risk Register - Education Department Risks and Mitigations Audit Committee 24 Risk Register - Education Department Risks and Executive summary and recommendations Introduction At its meeting on 26 September 2008, the Audit Committee instructed the Chief Executive

More information

This Policy supersedes the following Policy, which must now be destroyed:

This Policy supersedes the following Policy, which must now be destroyed: Document Title Reference Number Lead Officer Author(s) (name and designation) Ratified by Forensic Readiness Policy NTW(O)56 Lisa Quinn, Executive Director of Commissioning and Quality Assurance Angela

More information

Procurement of Project Management Training Services-

Procurement of Project Management Training Services- Statement of Work Table of Contents 2. Purpose and Scope... 3 3. Background Information... 3 4. Objectives... 3 5. Statement of Work... 3 6. Requirement Specifications for Services... 4 7. Requirement

More information

Risk Management at Statistics Canada

Risk Management at Statistics Canada Risk Management at Statistics Canada Presentation to Workshop on Risk Management Practices in Statistical Organizations J. Mayda April 25 th, 2016 Introduction Statistics Canada has had a formal Integrated

More information

Quality Assurance / Quality Control Plan

Quality Assurance / Quality Control Plan Quality Assurance / Quality Control Plan Table of Contents MANAGEMENT APPROACH... 3 SUBCONTRACT MANAGEMENT... 3 QUALITY MANAGEMENT APPROACH... 3 METHODOLOGY... 4 CONCEPT OF OPERATIONS... 5 QUALITY MANAGEMENT

More information

Enterprise Risk Management

Enterprise Risk Management Enterprise Risk Management Status Report October 22, 2003 Office of the City Auditor This page is intentionally blank. Office of the City Auditor Enterprise Risk Management Status Report History On August

More information

So, How Will You Audit a Risk Assessment in ISO 9001:2015?

So, How Will You Audit a Risk Assessment in ISO 9001:2015? So, How Will You Audit a Risk Assessment in ISO 9001:2015? Bob Deysher Senior Consultant Quality Support Group, Inc. bob.deysher@qualitysupportgroup.com 2017 QSG, Inc. Inc. Questions? Does ISO 9001:2015

More information

Risk & Opportunities

Risk & Opportunities Page 1 of 11 Risk & Opportunities Ghantoot Transport & General Contracting L.L.C Roads & Infrastructure Division P.O. Box: 30541 Abu Dhabi, UAE Tel: +971 2 641 9004 Fax: +971 2 641 9003 Website: www.ghantootgroup.com

More information